CVE-2019-9500
Broadcom brcmfmac driver is vulnerable to a heap buffer overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
El controlador Broadcom brcmfmac WiFi antes de commit 1b5e2423164b3670e8bc9174e4762d297990deff, es vulnerable a un desbordamiento del búfer de la pila. Si es configurada la funcionalidad Wake-up on Wireless LAN, una trama de evento malicioso puede ser construida para desencadenar un desbordamiento del búfer de la pila en la función brcmf_wowl_nd_results. Esta vulnerabilidad puede ser explotada con chipsets comprometidos para comprometer el host, o cuando es usada en combinación con CVE-2019-9503, puede ser usada remotamente. En el peor de los casos, mediante el envío de paquetes WiFi especialmente diseñados, un atacante remoto no autenticado puede ejecutar código arbitrario sobre un sistema vulnerable. Más típicamente, esta vulnerabilidad resultará en condiciones de denegación de servicio.
If the Wake-up on Wireless LAN functionality is configured in the brcmfmac driver, which only works with Broadcom FullMAC chipsets, a malicious event frame can be constructed to trigger a heap buffer overflow in the brcmf_wowl_nd_results() function. This vulnerability can be exploited by compromised chipsets to compromise the host, or when used in combination with another brcmfmac driver flaw (CVE-2019-9503), can be used remotely. This can result in a remote denial of service (DoS). Due to the nature of the flaw, a remote privilege escalation cannot be fully ruled out.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-01 CVE Reserved
- 2019-05-15 CVE Published
- 2023-05-21 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://kb.cert.org/vuls/id/166939 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff | 2023-01-19 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2019-9500 | 2019-12-10 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1701224 | 2019-12-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Brcmfmac Driver Search vendor "Broadcom" for product "Brcmfmac Driver" | - | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.5 < 4.9.181 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.5 < 4.9.181" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.10 < 4.14.123 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.10 < 4.14.123" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.15 < 4.19.47 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.15 < 4.19.47" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.20 < 5.0.20 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.0.20" | - |
Affected
|